Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 346 808

Количество 346 808

github логотип

GHSA-28p8-w9v3-x57w

около 4 лет назад

The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.

EPSS: Низкий
github логотип

GHSA-28p8-v452-44mv

около 4 лет назад

FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-28p8-9mj2-9g7v

11 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery allows Stored XSS. This issue affects Fusion Page Builder : Extension – Gallery: from n/a through 1.7.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-28p8-98p7-q6xq

7 месяцев назад

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-28p8-84f4-q826

около 4 лет назад

The ANSendForSharedReview method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

EPSS: Низкий
github логотип

GHSA-28p7-rxh6-3h6x

больше 2 лет назад

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote attacker to cause a temporary Denial of Service condition for a certain period of time in Ethernet communication of the products by performing TCP SYN Flood attack.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28p7-hfw7-j5qp

около 4 лет назад

Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Absence Management.

EPSS: Низкий
github логотип

GHSA-28p7-f6h6-3jh3

больше 1 года назад

LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-28p6-384f-vhg4

около 4 лет назад

Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

EPSS: Средний
github логотип

GHSA-28p5-7rg4-8v99

около 4 лет назад

Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )

EPSS: Низкий
github логотип

GHSA-28p4-crp9-2q2x

4 месяца назад

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-28p4-5j5m-924h

4 месяца назад

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets or Nodes pages, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information.

CVSS3: 8.9
EPSS: Низкий
github логотип

GHSA-28p3-mchr-9frj

около 4 лет назад

Deserialization of Untrusted Data in Jenkins

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-28p3-2x22-g64c

почти 4 года назад

In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07129717; Issue ID: ALPS07129717.

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-28p2-p7pc-m535

около 4 лет назад

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token.

EPSS: Низкий
github логотип

GHSA-28mw-j8x6-mf8x

10 месяцев назад

PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send a POST request changing currently logged user's password to defined by the attacker value. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-28mr-3phc-39gr

около 4 лет назад

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8345.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-28mq-w7hj-99g5

около 4 лет назад

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

EPSS: Низкий
github логотип

GHSA-28mp-g2wm-23p3

около 3 лет назад

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

CVSS3: 6
EPSS: Низкий
github логотип

GHSA-28mp-cx45-6mwq

больше 4 лет назад

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-28p8-w9v3-x57w

The wp_ajax_save_fbe_settings and wp_ajax_delete_fbe_settings AJAX actions of the Facebook for WordPress plugin before 3.0.4 were vulnerable to CSRF due to a lack of nonce protection. The settings in the saveFbeSettings function had no sanitization allowing for script tags to be saved.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28p8-v452-44mv

FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.

CVSS3: 9.8
4%
Низкий
около 4 лет назад
github логотип
GHSA-28p8-9mj2-9g7v

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion Page Builder : Extension – Gallery allows Stored XSS. This issue affects Fusion Page Builder : Extension – Gallery: from n/a through 1.7.6.

CVSS3: 6.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-28p8-98p7-q6xq

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package identifiers.

CVSS3: 3.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-28p8-84f4-q826

The ANSendForSharedReview method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.

6%
Низкий
около 4 лет назад
github логотип
GHSA-28p7-rxh6-3h6x

Insufficient Resource Pool vulnerability in Ethernet function of Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote attacker to cause a temporary Denial of Service condition for a certain period of time in Ethernet communication of the products by performing TCP SYN Flood attack.

CVSS3: 5.3
1%
Низкий
больше 2 лет назад
github логотип
GHSA-28p7-hfw7-j5qp

Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Absence Management.

1%
Низкий
около 4 лет назад
github логотип
GHSA-28p7-f6h6-3jh3

LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.php

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-28p6-384f-vhg4

Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.

18%
Средний
около 4 лет назад
github логотип
GHSA-28p5-7rg4-8v99

Reading on uninitialized buffer may cause UB ( `gfx_auxil::read_spirv()` )

около 4 лет назад
github логотип
GHSA-28p4-crp9-2q2x

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

CVSS3: 6.4
0%
Низкий
4 месяца назад
github логотип
GHSA-28p4-5j5m-924h

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a JavaScript payload. When the victim views the Assets or Nodes pages, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information.

CVSS3: 8.9
0%
Низкий
4 месяца назад
github логотип
GHSA-28p3-mchr-9frj

Deserialization of Untrusted Data in Jenkins

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-28p3-2x22-g64c

In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07129717; Issue ID: ALPS07129717.

CVSS3: 6.7
0%
Низкий
почти 4 года назад
github логотип
GHSA-28p2-p7pc-m535

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token.

2%
Низкий
около 4 лет назад
github логотип
GHSA-28mw-j8x6-mf8x

PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send a POST request changing currently logged user's password to defined by the attacker value. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

CVSS3: 4.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-28mr-3phc-39gr

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed, aka "LNK Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8345.

CVSS3: 8.8
19%
Средний
около 4 лет назад
github логотип
GHSA-28mq-w7hj-99g5

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

2%
Низкий
около 4 лет назад
github логотип
GHSA-28mp-g2wm-23p3

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below.

CVSS3: 6
1%
Низкий
около 3 лет назад
github логотип
GHSA-28mp-cx45-6mwq

The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination with WooCommerce, the email address of orders can be retrieved

CVSS3: 4.3
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу